Tuesday, 16 September 2025
28.2 C
Singapore
32.1 C
Thailand
29.4 C
Indonesia
27 C
Philippines

88% of top Asia Pacific companies still vulnerable to email fraud amid rising cyber threats

88% of top Asia Pacific companies lack strong email security, exposing customers to cyber threats as phishing attacks surge. Experts urge action.

A new report from cybersecurity firm Proofpoint reveals that 88% of top organisations in Asia Pacific are failing to implement the highest level of email authentication, leaving their customers and stakeholders at risk of email fraud. As phishing attacks surged by nearly 60% in 2024, businesses across the region remain highly vulnerable to domain spoofing and impersonation scams.

The findings are based on an analysis of Domain-based Message Authentication, Reporting and Conformance (DMARC) adoption among Asia Pacific companies listed on the Forbes Global 2000. DMARC is an email validation protocol that prevents cybercriminals from faking an organisation’s domain to send fraudulent emails. Despite its effectiveness in blocking phishing attempts, only 12% of the region’s largest businesses have enforced DMARC at the highest level.

“Email remains the most common and critical threat vector across industries. It’s encouraging that many leading companies in Asia Pacific have taken proactive steps to protect their customers from email fraud,” said George Lee, Senior Vice President of Asia Pacific and Japan at Proofpoint. “However, the rising frequency, sophistication, and cost of cyberattacks make it especially concerning that many remain highly vulnerable, exposing them to significant risks from malicious email-based threats such as phishing. Prioritising robust cybersecurity measures is essential to safeguard against these threats and protect customers’ valuable data.”

Australia leads in email security, while Japan, South Korea, and China lag behind

The report shows stark differences in DMARC adoption across Asia Pacific. Australia leads the region, with 71% of its top companies enforcing DMARC at the highest level (reject), meaning suspicious emails are blocked outright. In contrast, less than 20% of large businesses in Japan, South Korea, China, and Thailand have implemented the same level of protection.

Key findings from the report include:

Australia has the highest adoption rate, with 71% of its top companies setting DMARC to reject, and all major organisations analysed having a DMARC record in place. Singapore follows with 46.2% of businesses enforcing DMARC at the strictest level, though 23.1% lack any protection, leaving them exposed to phishing and email fraud. In India, 50% of leading firms have implemented the strongest DMARC settings, while 30.9% use a lower quarantine setting and 11.8% have no record.

In contrast, Japan has one of the lowest adoption rates, with only 7.4% of its major organisations enforcing DMARC at the reject level. A majority (65.6%) are still in monitoring mode, which collects data but does not actively prevent email fraud. South Korea fares even worse, with just 1.8% implementing DMARC at the quarantine level, none at the reject level, and 51.8% lacking any DMARC record. In Thailand, 17.6% of organisations enforce the reject policy, 17.6% use quarantine, and 52.9% remain at the monitoring stage.

China has one of the weakest security postures, with just 4.2% of its top companies using the strictest DMARC setting, while a staggering 71.8% have no email authentication in place at all. This leaves businesses and their customers highly vulnerable to phishing scams and impersonation attacks.

Push for stronger security measures amid compliance requirements

Several global email providers, including Google, Yahoo, and Apple, have taken steps to enforce stronger email authentication. In October 2023, they announced new requirements for bulk email senders, including the use of DMARC, to curb spam and phishing attempts.

Additionally, organisations handling payment data must comply with the latest Payment Card Industry Data Security Standard (PCI DSS v4.0.1), which mandates DMARC implementation by 31 March 2025. Non-compliance could result in financial penalties and increased security risks.

Proofpoint recommends that organisations take immediate action to strengthen their email security. Businesses should implement DMARC by setting it to reject, which prevents domain spoofing and ensures fraudulent emails do not reach inboxes. Companies should seek expert guidance to avoid mistakenly blocking legitimate emails.

Equally important is educating employees about phishing attempts, particularly those impersonating colleagues, suppliers, or customers. Training staff to identify suspicious emails can reduce the risk of falling victim to cyber threats. Additionally, businesses should enforce strong password policies, requiring employees to use complex passwords, update them regularly, and avoid reusing them across accounts.

As cyber threats continue to grow, businesses in Asia Pacific must prioritise email security to protect their reputation and customers from rising phishing attacks.

Hot this week

Kodak launches a mini camera that fits on a keyring

Kodak’s tiny Charmera camera fits on a keyring, shoots photos and video, and has become a sold-out collectable after launch.

Ulanzi OA-14 Camera Cage for Osmo Action 3/4/5 review: Rugged protection with creative flexibility

Ulanzi OA-14 adds rugged protection and accessory mounts to the DJI Osmo Action 5 while keeping battery swaps quick and easy. It is also compatible with the Osmo Action 3 and 4.

Agora expands OpenAI partnership to strengthen conversational AI offerings

Agora expands its partnership with OpenAI, integrating the Realtime API into its platform to power more natural multimodal conversational AI.

ASUS showcases ProArt displays, AI PCs and creator solutions at IBC 2025

ASUS unveils new ProArt displays, laptops, mini PCs and networking solutions at IBC 2025, showcasing AI tools for creators.

Amazon plans AR glasses for delivery drivers as early as next year

Amazon is developing AR glasses for delivery drivers, aiming to launch next year with built-in navigation and delivery guidance tools.

Biwin unveils Mini SSD, a tiny storage device that could replace microSD cards

Biwin launches Mini SSD, a tiny yet powerful storage device that could replace microSD cards if industry standards are adopted.

Apple brings major upgrades to Powerbeats Pro 2 with iOS 26

Apple adds heart rate, fitness, and smart usability upgrades to Powerbeats Pro 2 with iOS 26, launching on 15 September.

UltraGreen.ai secures US$188 million anchor investment at US$1.3 billion valuation

UltraGreen.ai secures US$188 million anchor investment led by 65EP, Vitruvian, and August, valuing the firm at US$1.3 billion.

ConnectingDNA launches AI-powered DNA wellness marketplace in Singapore

ConnectingDNA launches the world’s first AI-powered DNA wellness marketplace in Singapore, offering personalised health insights and secure data protection.

Related Articles

Popular Categories